PRIVACY POLICY

Cache Of Credits — Twisted Lunacy (ABN 21 979 134 918) — Effective 15 September 2026 — v1.0

This policy explains what we collect, why, where it goes and what you can do about it. It is written to comply with the Australian Privacy Act 1988 (APPs), the EU and UK GDPR, applicable US state privacy laws (including the CCPA/CPRA), Canada's PIPEDA and New Zealand's Privacy Act 2020. Short version: we collect what the game needs to run, we don't sell it, verification photos self-destruct in 24 hours, and you can delete everything in-app.

1. Who we are

Cache Of Credits is operated by Twisted Lunacy (ABN 21 979 134 918), Australia ("we", "us"). Contact: admin@cacheofcredits.com. For EU/UK data-protection queries, the same address reaches the privacy officer.

2. What we collect and why

3. What we don't do

4. Legal bases (GDPR / UK GDPR)

Where the GDPR applies: account and gameplay processing is necessary to perform our contract with you (providing the game); location processing during hunts is contract performance and you control it through device permissions; anti-cheat and security processing is our legitimate interest in a fair game; diagnostics are legitimate interest with minimised data; anything else is consent, requested before collection and withdrawable in-app.

5. Where your data goes

Our infrastructure runs on Google Firebase (data hosted in the United States) and error reporting on Sentry (US). Under APP 8 and GDPR Chapter V, cross-border transfers rely on the providers' standard contractual clauses and equivalent safeguards. Purchase processing occurs with Apple, Google and RevenueCat under their own policies.

6. How long we keep it

7. Your rights

Wherever you are, you can: access your data (in-app export, GDPR Art. 15 / APP 12 / CCPA right to know), correct it (APP 13 / GDPR Art. 16), delete it (in-app: Profile → Delete Account — GDPR Art. 17 erasure, CCPA deletion; the cascade removes your profile, hunt history, photos, and leaderboard entries), export it in machine-readable form (GDPR Art. 20), and complain to a regulator — the OAIC (Australia), your EU supervisory authority, the UK ICO, or your state Attorney-General (US). We will never discriminate against you for exercising any right.

California residents: we do not sell or share personal information as defined by the CCPA/CPRA, so no "Do Not Sell Or Share" opt-out is required — if that ever changes, this policy and the app will present one first.

8. Security

Data in transit is encrypted (TLS). Passwords are hashed. Photo verification runs entirely server-side. Access to production data is restricted and logged. No system is perfectly secure; if a breach occurs that is likely to result in serious harm, we will notify affected users and the OAIC within 30 days, and where GDPR applies, the supervisory authority within 72 hours.

9. Children

Cache Of Credits is for adults 18+. The age gate blocks under-18 signups before any account exists and before any purchase is possible. If we learn an account belongs to a minor, we delete it.

10. Changes

Material changes will be announced in-app and on this page before they take effect, with the version and date updated above.